Bug#1036062: frr: CVE-2023-31490
Hi, On Tue, 11 Jul 2023 13:47:46 +0300 Adrian Bunk wrote: > On Tue, Jun 13, 2023 at 03:17:52PM +0200, David Lamparter wrote: > > Fixed upstream in 9f1ba873637fd6ce4a2d366eafcf41402775852b on stable/8.4 > > branch. > > > > Debian fix incoming with bump to 8.4.4 if that's OK? That wouldn't be a > > targeted security fix, but FRR minor versions are bugfix-only. > > These two CVEs are not marked "no-dsa" so far, it would be for Salvatore > or someone else from the security team to decide what is acceptable if > they want to publish a security advisory for bookworm. > > > -equi > > cu > Adrian > I've read through upstream changes from 8.4.2 to 8.4.4 and agreed it is a stable bugfix-only update. I have talked to Salvatore and believe it's a good idea to upload 8.4.4 through bookworm-security to address those issues. Would you mind preparing and uploading it to security-master? Please use a lower version number than testing, e.g. 8.4.4-1~deb12u1. Thanks, Aron
Bug#1036061: Bug#1036062: frr: CVE-2023-31490
On Tue, Jun 13, 2023 at 03:17:52PM +0200, David Lamparter wrote: > Fixed upstream in 9f1ba873637fd6ce4a2d366eafcf41402775852b on stable/8.4 > branch. > > Debian fix incoming with bump to 8.4.4 if that's OK? That wouldn't be a > targeted security fix, but FRR minor versions are bugfix-only. These two CVEs are not marked "no-dsa" so far, it would be for Salvatore or someone else from the security team to decide what is acceptable if they want to publish a security advisory for bookworm. > -equi cu Adrian
Bug#1036062: frr: CVE-2023-31490
Argh, wrong bug, previous mail was for 1036061. On Tue, Jun 13, 2023 at 03:17:52PM +0200, David Lamparter wrote: > Fixed upstream in 9f1ba873637fd6ce4a2d366eafcf41402775852b on stable/8.4 > branch. CVE-2023-31489 / 1036062 was fixed upstream on master but not backported to 8.4 yet; now pending upstream CI & review in https://github.com/FRRouting/frr/pull/13782 8.4.4 release is expected upstream shortly, including fixes for both this and CVE-2023-31490. -equi
Bug#1036062: frr: CVE-2023-31490
Fixed upstream in 9f1ba873637fd6ce4a2d366eafcf41402775852b on stable/8.4 branch. Debian fix incoming with bump to 8.4.4 if that's OK? That wouldn't be a targeted security fix, but FRR minor versions are bugfix-only. -equi
Bug#1036062: frr: CVE-2023-31490
Source: frr Version: 8.4.2-1 Severity: grave Tags: security upstream Forwarded: https://github.com/FRRouting/frr/issues/13099 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for frr. CVE-2023-31490[0]: | An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to | cause a denial of service via the bgp_attr_psid_sub() function. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-31490 https://www.cve.org/CVERecord?id=CVE-2023-31490 [1] https://github.com/FRRouting/frr/issues/13099 Please adjust the affected versions in the BTS as needed. Regards, Salvatore